AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66760

MEDIUM · CVSS 6.4 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

SAP Approuter is vulnerable due to improper validation of client certificates in specific callback flows, allowing an attacker with low privileges to potentially impersonate a trusted internal component if they possess a matching certificate from the same trusted authority. While the attack's complexity makes it challenging to execute, successful exploitation could significantly compromise the integrity of the system. Organizations using SAP Approuter should prioritize addressing this vulnerability to safeguard their internal communications and prevent unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66760
Severity
MEDIUM
CVSS
6.4
EPSS
0.12%

Original NVD Description

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.